-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly states that Drupal 8's file_save_upload() lacked filename sanitization for leading/trailing dots that existed in Drupal 7. The advisory directly references this function as the patched component, and the CWE-434 context confirms this is an unrestricted file upload vulnerability. The file path is inferred from standard Drupal 8 module structure where file handling functions reside in core/modules/file.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| drupal/drupal | composer | >= 8.0.0, < 8.7.11 | 8.7.11 |
| drupal/drupal | composer | >= 8.8.0, < 8.8.1 | 8.8.1 |
Ongoing coverage of React2Shell